fix(security): validate bundle and clean runtime secrets

This commit is contained in:
2026-07-12 11:52:02 +02:00
parent 385646d574
commit 449a333365
5 changed files with 94 additions and 20 deletions
+8
View File
@@ -47,3 +47,11 @@ that neither secret values nor bundle/file metadata are inherited by the Pi chil
The rotation helper retains its old/new scratch-file CLI contract; smoke tests keep those files
outside Compose and mount only the bundle.
## Whole-branch review fixes
- `core-entrypoint.sh` validates `THT_SECRETS_FILE` fail-closed before optional lookups; malformed,
duplicate, unknown, oversized, or overlong bundles stop startup with sanitized diagnostics.
- Runtime password files are cleaned after child exit via signal forwarding and `wait`, rather
than being orphaned by `exec`.
- The shell loader accepts CRLF bundles (Windows/Notepad) consistently with the TypeScript loader.